<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Privacy Law Network News</title>
        <link>https://www.privacylawnetwork.com/news.html</link>
        <atom:link href="https://www.privacylawnetwork.com/news/feed.xml" rel="self" type="application/rss+xml"/>
        <description>Privacy law enforcement, legislation and court rulings, reported from primary sources.</description>
        <language>en-us</language>
        <lastBuildDate>Mon, 21 Sep 2026 12:00:00 GMT</lastBuildDate>
        <item>
            <title>Alberta and British Columbia Each Have a Personal Information Protection Act. They Are Not the Same Law</title>
            <link>https://www.privacylawnetwork.com/news/alberta-bc-private-sector-privacy-acts.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/alberta-bc-private-sector-privacy-acts.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>Two federal exemption orders registered on the same day in 2004 let Alberta's and British Columbia's private-sector privacy statutes displace PIPEDA inside each province. The Acts share a name and identical fine ceilings, but only Alberta's requires breach reporting, they define employee information and treat non-profits differently, and BC has credit-reporting amendments due in 2027.</description>
            <category>Canada (PIPEDA)</category>
        </item>
        <item>
            <title>Brazil's Encarregado Regulation: The Appointment Paperwork, the Website Notice and the Conflict Rules</title>
            <link>https://www.privacylawnetwork.com/news/anpd-encarregado-regulation.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/anpd-encarregado-regulation.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>The LGPD says a controller must appoint an encarregado and publish how to reach them, and leaves the rest to the regulator. Resolution CD/ANPD No. 18 of 16 July 2024 supplies it: a written, dated and signed act of appointment, a named substitute, a minimum content for the public notice, five duties the organisation owes its encarregado, and a conflict-of-interest regime that can lead to sanctions.</description>
            <category>Brazil (LGPD)</category>
        </item>
        <item>
            <title>China's Network Data Regulations Put a Price on Scraping, Recommendation Switches and Important Data</title>
            <link>https://www.privacylawnetwork.com/news/china-network-data-security-regulations.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/china-network-data-security-regulations.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Regulations on Network Data Security Management are an administrative regulation of the State Council, made to implement three statutes at once rather than one. They define who a network data processor is, add concrete rules on privacy notices, portability and personalised recommendation, impose annual risk reporting on holders of important data, and set their own fine schedule.</description>
            <category>China (PIPL)</category>
        </item>
        <item>
            <title>China's PIPL Audit Duty Waited Four Years for a Frequency, a Trigger List and an Annex of 27 Checks</title>
            <link>https://www.privacylawnetwork.com/news/china-personal-information-compliance-audits.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/china-personal-information-compliance-audits.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>Article 54 of China's Personal Information Protection Law has required regular compliance audits since November 2021, without saying how often, by whom or against what. The CAC's Measures for Personal Information Protection Compliance Audits, in force since 1 May 2025, supply those answers, and add a second route by which a regulator can order an outside audit at the processor's expense.</description>
            <category>China (PIPL)</category>
        </item>
        <item>
            <title>Public Act 25-113 Rewrote the Connecticut Data Privacy Act on July 1, 2026, and a 2026 Act Rewrites Part of It Again in October</title>
            <link>https://www.privacylawnetwork.com/news/connecticut-data-privacy-act-2025-amendments.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/connecticut-data-privacy-act-2025-amendments.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>Substitute Senate Bill 1295 became Public Act 25-113 on June 24, 2025. Its Data Privacy Act sections took effect together on July 1, 2026: a lower threshold, two no-threshold triggers, more sensitive data, profiling rights, impact assessments and a ban on selling teenagers' data. Public Act 26-64 amends several of the same sections again from October 1, 2026.</description>
            <category>State Comprehensive Privacy Laws</category>
        </item>
        <item>
            <title>The Justice Department's Bulk Sensitive Data Rule: Six Countries, Six Data Categories, and Two Compliance Dates in 2025</title>
            <link>https://www.privacylawnetwork.com/news/doj-bulk-sensitive-data-rule.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/doj-bulk-sensitive-data-rule.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>Executive Order 14117 directed the Attorney General to bar or condition transactions that give six foreign governments, and persons tied to them, access to Americans' bulk sensitive data. The resulting rule, 28 CFR part 202, took effect April 8, 2025. Its due diligence, audit and reporting duties followed on October 6, 2025. The only change to the text since publication is a one-line correction.</description>
            <category>Cross-Border Transfers</category>
        </item>
        <item>
            <title>Five Years of the Civil Cyber-Fraud Initiative: Sixteen Settlements, Ten Whistleblower Suits and No Judgment</title>
            <link>https://www.privacylawnetwork.com/news/doj-civil-cyber-fraud-initiative.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/doj-civil-cyber-fraud-initiative.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Justice Department launched the Civil Cyber-Fraud Initiative on October 6, 2021 to pursue government contractors and grantees under the False Claims Act for knowing cybersecurity failures. This publication located sixteen resolved matters announced in DOJ releases through September 1, 2026, totaling about $69.1 million. Every one settled, and most began as whistleblower suits.</description>
            <category>Data Security Rules</category>
        </item>
        <item>
            <title>The Data Protection Board of India Exists in Law, Has a Pay Scale and a Selection Committee, and Has No Members Yet</title>
            <link>https://www.privacylawnetwork.com/news/india-data-protection-board-procedure.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/india-data-protection-board-procedure.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Data Protection Board of India was established by Gazette notification on 13 November 2025, with its head office in the National Capital Region. MeitY invited applications for a Chairperson and four Members in May 2026, and no appointment had been notified by 21 September 2026. This explainer covers its staffing, its digital procedure and which of its powers are not yet in force.</description>
            <category>India (DPDP Act)</category>
        </item>
        <item>
            <title>India's DPDP Breach Rule Has No Harm Threshold and a 72-Hour Report, and It Does Not Start Until 2027</title>
            <link>https://www.privacylawnetwork.com/news/india-dpdp-breach-intimation.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/india-dpdp-breach-intimation.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>Section 8(6) of India's Digital Personal Data Protection Act requires a Data Fiduciary to tell the Data Protection Board and each affected individual about a personal data breach, and rule 7 of the 2025 Rules fills in the content and a 72-hour clock. Both sit in the commencement tranche that starts eighteen months after 13 November 2025, while CERT-In's six-hour incident reporting already applies.</description>
            <category>India (DPDP Act)</category>
        </item>
        <item>
            <title>The LGPD's Small-Business Regime: Who Qualifies, Who Is Excluded and Which Clocks Run at Double Speed</title>
            <link>https://www.privacylawnetwork.com/news/lgpd-small-processing-agents-regulation.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/lgpd-small-processing-agents-regulation.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>Resolution CD/ANPD No. 2 of 2022 gives micro and small enterprises, startups, non-profits and individuals acting as controllers or processors a lighter version of the LGPD: a simplified record of processing, no mandatory encarregado, and doubled deadlines. Three exclusions take it away, the ANPD can withdraw it case by case, and a 2024 regulation rewrote one deadline rule.</description>
            <category>Brazil (LGPD)</category>
        </item>
        <item>
            <title>New York's Child Data Protection Act: Nine Sections, a Consent Form With Four Conditions, and Rules Still Unproposed</title>
            <link>https://www.privacylawnetwork.com/news/new-york-child-data-protection-act.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/new-york-child-data-protection-act.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>Chapter 121 of the Laws of 2024 added article 39-FF, sections 899-ee to 899-mm, to New York's General Business Law. It has applied since June 20, 2025 to operators whose users are known minors or whose services are primarily directed to minors. The Attorney General issued an advance notice in 2024 and implementation guidance in May 2025, but has not published proposed rules.</description>
            <category>State Comprehensive Privacy Laws</category>
        </item>
        <item>
            <title>Canada's Meaningful Consent Guidelines Sort Themselves Into Must and Should. Here Is Which Is Which</title>
            <link>https://www.privacylawnetwork.com/news/opc-meaningful-consent-guidelines.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/opc-meaningful-consent-guidelines.html</guid>
            <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Guidelines for obtaining meaningful consent were issued jointly by the federal Privacy Commissioner and the Alberta and British Columbia commissioners in May 2018 and last modified in August 2025. They set seven principles, four elements that must be emphasised, three triggers for express consent and an under-13 position on children, and label each item an obligation or a best practice.</description>
            <category>Canada (PIPEDA)</category>
        </item>
        <item>
            <title>CAN-SPAM's Primary Purpose Rule: How the FTC Sorts Commercial From Transactional Email</title>
            <link>https://www.privacylawnetwork.com/news/can-spam-commercial-and-transactional-messages.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/can-spam-commercial-and-transactional-messages.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>Almost every CAN-SPAM duty depends on a threshold question the statute left to the FTC: is this email commercial, transactional, or something else? The answer comes from a 2005 rule that looks at the subject line, at what sits at the top of the body, and at the overall impression of the message, and the Commission has declined every request since to redraw it.</description>
            <category>CAN-SPAM</category>
        </item>
        <item>
            <title>CAN-SPAM Opt-Out Requirements: The Mechanism, the Ten-Day Clock and the Suppression List</title>
            <link>https://www.privacylawnetwork.com/news/can-spam-opt-out-mechanics.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/can-spam-opt-out-mechanics.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>CAN-SPAM never asks for permission before the first commercial email. Its control is the objection, and the statute and the FTC's rule regulate that objection closely: what channel carries it, how long the channel stays open, how quickly sending stops, what a sender may not demand in exchange, and what may be done with the address afterwards.</description>
            <category>CAN-SPAM</category>
        </item>
        <item>
            <title>The CFPB's Personal Financial Data Rights Rule: The Text of Part 1033 and the Injunction That Froze It</title>
            <link>https://www.privacylawnetwork.com/news/cfpb-personal-financial-data-rights-rule.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/cfpb-personal-financial-data-rights-rule.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Personal Financial Data Rights Rule, 12 CFR part 1033, requires banks, card issuers and other data providers to make consumer financial data available to consumers and authorized third parties. The rule remains on the books, but since October 29, 2025 the CFPB has been enjoined from enforcing it while it reconsiders the rule, and appeals from that order are paused.</description>
            <category>GLBA</category>
        </item>
        <item>
            <title>CIRCIA's 72-Hour and 24-Hour Reporting Clocks Are Federal Law, and Still Have No Start Date</title>
            <link>https://www.privacylawnetwork.com/news/circia-cyber-incident-reporting.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/circia-cyber-incident-reporting.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Cyber Incident Reporting for Critical Infrastructure Act of 2022 wrote two reporting clocks into federal law but left their start date, and the definitions of who reports and what, to a CISA rulemaking that was due in October 2025. This sets out what the statute fixes, what the 2024 proposal would add, and where the rulemaking stood on September 14, 2026.</description>
            <category>Ransomware</category>
            <category>Breach Notification</category>
        </item>
        <item>
            <title>The FTC Negative Option Rule After Click-to-Cancel: What Was Vacated and What Part 425 Says Now</title>
            <link>https://www.privacylawnetwork.com/news/ftc-negative-option-rule.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/ftc-negative-option-rule.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>Between late 2024 and early 2026, 16 CFR Part 425 said three different things. The FTC's click-to-cancel amendments took effect, were vacated by the Eighth Circuit on procedural grounds weeks before full compliance was due, and were replaced by the 1973 book-club rule. This sets out what each version says, why the court ruled as it did, and what federal law governs online subscriptions today.</description>
            <category>Dark Patterns</category>
            <category>FTC Enforcement</category>
        </item>
        <item>
            <title>How the ICO Calculates a UK GDPR Fine: The Five Steps in Its Data Protection Fining Guidance</title>
            <link>https://www.privacylawnetwork.com/news/ico-fining-guidance.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/ico-fining-guidance.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Information Commissioner's Office published its Data Protection Fining Guidance on 18 March 2024 under section 160 of the Data Protection Act 2018. It explains when the regulator issues a penalty notice and how it reaches an amount, from a seriousness band through a turnover adjustment to a final check against the statutory cap. Both are set out here.</description>
            <category>UK Data Protection</category>
        </item>
        <item>
            <title>The NAIC Insurance Data Security Model Law: What Model #668 Requires and How Eight States Rewrote It</title>
            <link>https://www.privacylawnetwork.com/news/insurance-data-security-model-law.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/insurance-data-security-model-law.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.</description>
            <category>Data Security Rules</category>
        </item>
        <item>
            <title>The Maryland Online Data Privacy Act as Enacted: New Section Numbers, No Consent Route and a 2026 Rewrite</title>
            <link>https://www.privacylawnetwork.com/news/maryland-online-data-privacy-act.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/maryland-online-data-privacy-act.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Maryland Online Data Privacy Act has applied since October 1, 2025, but not at the section numbers its bill record gives, or in the form its chapter law's plain text suggests. This post sets out the statute as the General Assembly now publishes it, the Attorney General's reading of its minimization rule, and the immigration-enforcement amendments effective July 1, 2026.</description>
            <category>State Comprehensive Privacy Laws</category>
        </item>
        <item>
            <title>New York's SHIELD Act: The Section 899-bb Security Requirement and the Breach Law Changes Since 2019</title>
            <link>https://www.privacylawnetwork.com/news/new-york-shield-act-data-security.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/new-york-shield-act-data-security.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>The SHIELD Act of 2019 did two things: it widened New York's breach notification statute, General Business Law section 899-aa, and it added section 899-bb, a standalone duty to maintain reasonable data security. This sets out the security requirement as enacted, the routes to deemed compliance, and the three later chapters that changed section 899-aa without touching section 899-bb.</description>
            <category>Data Security Rules</category>
            <category>Breach Notification</category>
        </item>
        <item>
            <title>When Ransomware Encrypts Health Data, HIPAA Presumes a Breach: How the Presumption Works</title>
            <link>https://www.privacylawnetwork.com/news/ransomware-hipaa-breach-presumption.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/ransomware-hipaa-breach-presumption.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>HHS does not treat ransomware as a mere outage outside the breach rules. Its Office for Civil Rights reads encryption by an attacker as an acquisition of the data, which brings the incident within the regulatory presumption of breach at 45 CFR 164.402. This sets out where that presumption came from, what rebutting it involves, and the clocks that follow when it stands.</description>
            <category>Ransomware</category>
            <category>HIPAA</category>
        </item>
        <item>
            <title>State Dark Pattern Rules: How California, Colorado and Connecticut Void Manipulated Consent</title>
            <link>https://www.privacylawnetwork.com/news/state-dark-pattern-consent-rules.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/state-dark-pattern-consent-rules.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>California, Colorado and Connecticut define a dark pattern in nearly the same words, and each treats agreement obtained through one as no consent at all. What differs is the material around that sentence: an example-driven regulation in California, design and withdrawal rules in Colorado, and in Connecticut a statute that points to the FTC.</description>
            <category>Dark Patterns</category>
            <category>Consent Management</category>
        </item>
        <item>
            <title>Vermont's Age-Appropriate Design Code: What Act 63 Requires of Online Services From January 1, 2027</title>
            <link>https://www.privacylawnetwork.com/news/vermont-age-appropriate-design-code.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/vermont-age-appropriate-design-code.html</guid>
            <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
            <description>Vermont enacted its Age-Appropriate Design Code as Act 63 of 2025, signed June 12, 2025. The substantive duties begin on January 1, 2027, but the Attorney General's rulemaking powers took effect in July 2025 and proposed rules are open for comment until October 2, 2026. This post covers its definitions and duties and compares them with the California provisions the Ninth Circuit has ruled on.</description>
            <category>State Comprehensive Privacy Laws</category>
        </item>
        <item>
            <title>Colorado's AI Act and the Consequential Decision: What the Reenacted Part 17 Says</title>
            <link>https://www.privacylawnetwork.com/news/colorado-ai-act-consequential-decisions.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/colorado-ai-act-consequential-decisions.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>Colorado's 2024 artificial intelligence statute was delayed once, then repealed and reenacted before it ever took effect. Senate Bill 26-189, signed May 14, 2026, replaced part 17 of article 1 of title 6 with a framework keyed to automated decision-making technology. Consequential decision survived as the trigger; the algorithmic discrimination duty did not.</description>
            <category>Automated Decision-Making</category>
            <category>AI &amp; Privacy</category>
        </item>
        <item>
            <title>Cookie Consent Banner Requirements: What US State Law Actually Says</title>
            <link>https://www.privacylawnetwork.com/news/cookie-consent-banner-requirements.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/cookie-consent-banner-requirements.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>The banner that greets visitors to most American websites is not a creature of American statute. Neither the CCPA nor the Colorado Privacy Act requires one, and the California regulations mention banners chiefly to say when their design is unlawful. This sets out what each statute requires at the point of collection, and when each genuinely calls for consent.</description>
            <category>Adtech &amp; Cookies</category>
            <category>Consent Management</category>
        </item>
        <item>
            <title>Where the CPPA's Rulemaking Authority Comes From, and What It Covers</title>
            <link>https://www.privacylawnetwork.com/news/cppa-rulemaking-authority.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/cppa-rulemaking-authority.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>Proposition 24 established the California Privacy Protection Agency in December 2020, but the power to write CCPA regulations did not move to it on that date. The transfer was conditional, it completed in April 2022, and the Attorney General's own regulatory authority was never extinguished. This traces the grant, the condition, the board that exercises it, and what the agency has adopted.</description>
            <category>CPPA</category>
            <category>CCPA / CPRA</category>
        </item>
        <item>
            <title>Three Ways to Tell an Employee They Are Being Monitored</title>
            <link>https://www.privacylawnetwork.com/news/employee-electronic-monitoring-notice.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/employee-electronic-monitoring-notice.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>Three states condition workplace electronic monitoring on notice rather than on consent, and each builds the requirement differently. Connecticut makes a posted notice the legal notice. New York requires a notice on hiring and a posting. Delaware offers a choice between a daily electronic notice and a one-time acknowledged one.</description>
            <category>Workplace Monitoring</category>
            <category>Employee Privacy</category>
        </item>
        <item>
            <title>Consent to Face Analysis in a Job Interview: Four Statutes, Four Different Asks</title>
            <link>https://www.privacylawnetwork.com/news/facial-recognition-hiring-consent.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/facial-recognition-hiring-consent.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>Three states regulate what happens to an applicant's face during hiring, through four statutes that each define permission differently. Maryland asks for a signed waiver with four listed contents. Illinois asks for notice, an explanation and consent, and separately for a written release. Texas asks only that the individual be informed and consent before capture.</description>
            <category>Facial Recognition</category>
            <category>Biometric Privacy</category>
            <category>Employee Privacy</category>
        </item>
        <item>
            <title>Adverse Action Notices Under the FCRA: Two Notices, and What Each One Carries</title>
            <link>https://www.privacylawnetwork.com/news/fcra-adverse-action-notice.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/fcra-adverse-action-notice.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Fair Credit Reporting Act does not have one adverse action notice. It has a notice owed before a decision that only employers owe, and a notice owed after any adverse action taken on a consumer report by anyone. The two sit in different sections, carry different contents, and answer to different silences in the statute.</description>
            <category>FCRA</category>
            <category>Background Checks</category>
        </item>
        <item>
            <title>The FCRA Standalone Disclosure Requirement, as the Ninth Circuit Has Read It</title>
            <link>https://www.privacylawnetwork.com/news/fcra-standalone-disclosure-requirement.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/fcra-standalone-disclosure-requirement.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>Four published Ninth Circuit opinions have construed a single sentence of the Fair Credit Reporting Act: the requirement that an employment background check disclosure appear in a document that consists solely of the disclosure. Read in sequence, Syed, Gilberg, Walker and Luna map what may sit on the page, what the page is, and where the line still has not been drawn.</description>
            <category>Background Checks</category>
            <category>FCRA</category>
        </item>
        <item>
            <title>New Jersey's Vehicle Tracking Notice Law, and the Four Reprints That Made It</title>
            <link>https://www.privacylawnetwork.com/news/new-jersey-employee-vehicle-tracking.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/new-jersey-employee-vehicle-tracking.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>New Jersey's tracking device statute, N.J.S.A. 34:6B-22, was approved on January 18, 2022 and took effect ninety days later. It reached that form after four reprints that moved it from a fourth-degree crime to a civil penalty, from written consent to written notice, and from any tracking device to one designed for the sole purpose of tracking.</description>
            <category>Employee Privacy</category>
            <category>Workplace Monitoring</category>
        </item>
        <item>
            <title>State Data Broker Registries Compared: What Each One Actually Publishes</title>
            <link>https://www.privacylawnetwork.com/news/state-data-broker-registries.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/state-data-broker-registries.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>Registration statutes are usually compared by what they demand of a filer. They can also be compared by what they hand back to the public, and on that axis the four state registries are not alike. One publishes every answer as a downloadable file; the other three publish a search box. This reports what is readable off each, and what California's file disclosed.</description>
            <category>Data Brokers</category>
        </item>
        <item>
            <title>No Concrete Harm, No Standing: Inside TransUnion v. Ramirez</title>
            <link>https://www.privacylawnetwork.com/news/transunion-ramirez-concrete-harm.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/transunion-ramirez-concrete-harm.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>Decided 25 June 2021 by five votes to four, TransUnion LLC v. Ramirez took a jury verdict that had already been returned and removed three quarters of the class from federal court. This post reads the case as a case: the OFAC Name Screen product, the six-day trial, the arithmetic of the award, the reasoning on each of the three claims, and the two dissents.</description>
            <category>Standing &amp; Damages</category>
            <category>Privacy Litigation</category>
        </item>
        <item>
            <title>The Data (Use and Access) Act 2025 Arrived in Eight Instalments — and Two Sections Have Still Not Arrived</title>
            <link>https://www.privacylawnetwork.com/news/uk-data-use-and-access-act.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/uk-data-use-and-access-act.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>The Data (Use and Access) Act 2025 is a nine-part statute covering smart data schemes, digital identity, buried pipes, birth registers, data protection, a new regulator and much else. Its commencement is the part most easily got wrong: Royal Assent brought almost none of it into force, and a reader working from the Act alone cannot tell what is law today.</description>
            <category>UK Data Protection</category>
            <category>GDPR</category>
        </item>
        <item>
            <title>Three Circuits, One Preposition: The VPPA &quot;Consumer&quot; Split Reaches the Supreme Court</title>
            <link>https://www.privacylawnetwork.com/news/vppa-consumer-definition-circuit-split.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/vppa-consumer-definition-circuit-split.html</guid>
            <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
            <description>One phrase in the Video Privacy Protection Act — &quot;goods or services from a video tape service provider&quot; — has produced an open split among three courts of appeals over who may sue. The Supreme Court granted review on 26 January 2026 and has set argument for 14 October 2026. This post sets out what each opinion actually reasoned.</description>
            <category>VPPA</category>
            <category>Privacy Litigation</category>
        </item>
        <item>
            <title>Arbitration Clauses and Their Effect on Privacy Class Actions</title>
            <link>https://www.privacylawnetwork.com/news/arbitration-in-privacy-class-actions.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/arbitration-in-privacy-class-actions.html</guid>
            <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
            <description>A privacy class action filed against a company whose terms contain an arbitration clause is usually decided on a motion to compel long before any merits ruling. This post describes the Federal Arbitration Act machinery that governs those motions, the online assent cases that determine whether a clause was formed at all, and the narrow categories Congress and state legislatures have carved out.</description>
            <category>Privacy Class Actions</category>
        </item>
        <item>
            <title>The California Delete Act: Registration, DROP, and the Deadlines Written Into SB 362</title>
            <link>https://www.privacylawnetwork.com/news/california-delete-act-data-broker-registry.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/california-delete-act-data-broker-registry.html</guid>
            <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
            <description>California's Delete Act took an existing registry and attached machinery to it: one consumer request that reaches every registered broker, a 45-day processing cycle, a triennial third-party audit and a $200-a-day fine for not signing up. This reports what SB 362 and the 2025 amendment require, and the dates the statute and the DROP regulations set.</description>
            <category>Data Brokers</category>
            <category>CCPA / CPRA</category>
            <category>CPPA</category>
        </item>
        <item>
            <title>The CCPA Enforcement Record: Every Public Action, Its Penalty and What It Alleged</title>
            <link>https://www.privacylawnetwork.com/news/ccpa-enforcement-record.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/ccpa-enforcement-record.html</guid>
            <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
            <description>California is the only state whose comprehensive privacy law has produced a substantial public enforcement record, and it has two enforcers producing it. This charts the twelve publicly documented CCPA actions, the penalty in each, the document each rests on, and the allegations that recur across almost all of them.</description>
            <category>CCPA / CPRA</category>
            <category>CPPA</category>
        </item>
        <item>
            <title>The Amended COPPA Rule: What the FTC Changed, and When Each Piece Bound</title>
            <link>https://www.privacylawnetwork.com/news/coppa-rule-2025-amendments.html</link>
            <guid isPermaLink="true">https://www.privacylawnetwork.com/news/coppa-rule-2025-amendments.html</guid>
            <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
            <description>The FTC published amendments to the Children's Online Privacy Protection Rule on April 22, 2025. They added a separate-consent requirement for third-party disclosure, a written retention policy and a prohibition on indefinite retention, two new categories of personal information, a written security program, and staggered obligations for safe harbor programs.</description>
            <category>COPPA</category>
            <category>FTC Enforcement</category>
            <category>Consent Management</category>
        </item>
    </channel>
</rss>
